Python CGIHTTPServer "is_cgi ()" Security Restriction Bypass Vulnerability
Release date:
Updated on:
Affected Systems:
Python python 3.x
Python python 2.7.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-4650
Python is an object-oriented, literal translation computer programming language. The CGIHTTPServer module can be used to set simple HTTP servers.
Python 2.7.3 processes the "is_cgi ()" function (Lib/CGIHTTPServer. py). Attackers can exploit the directory traversal sequence to leak the source code of any CGI script and execute any python script.
<* Source: RedTeam Pentesting GmbH (http://www.redteam-pentesting.de /)
Link: http://secunia.com/advisories/59091/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Python
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Python:
Http://bugs.python.org/issue21766
RedTeam Pentesting GmbH:
Https://www.redteam-pentesting.de/en/advisories/rt-sa-2014-008/-python-cgihttpserver-file-disclosure-and-potential-code-execution
Python core programming version 2. (Wesley J. Chun). [Chinese version of hd pdf]
Python development technology details. (Zhou Wei, Zong Jie). [hd PDF scan version + book guide video + code]
Obtain Linux information using a Python script
Build a desktop algorithm transaction research environment using Python in Ubuntu
Python details: click here
Python: click here
This article permanently updates the link address: